Understanding Cybersecurity of Mobile Networks

Full Title:
Understanding Cybersecurity of Mobile Networks Act

Summary#

The bill requires the Assistant Secretary of Commerce for Communications and Information to deliver a report to two Congressional committees within 1 year of the law taking effect. The report must examine the cybersecurity of mobile service networks and how mobile networks and devices can be vulnerable to cyberattacks and surveillance by adversaries. It must assess whether mobile service providers have addressed vulnerabilities identified by researchers, standards groups, industry experts, and Federal agencies (including NTIA, NIST, and parts of DHS such as CISA and S&T).

The report must also discuss whether customers consider cybersecurity when buying mobile service and devices, the availability of tools to help evaluate cyber risk, and the degree to which providers follow cybersecurity best practices and risk frameworks. It must estimate and discuss how common and effective encryption and authentication methods are for mobile service, network equipment, phones, operating systems, and apps. The report must identify barriers to adopting stronger encryption and to phasing out older vulnerable methods. It must estimate how widespread and effective technologies are that authenticate legitimate mobile service and how common, costly, and available cell site simulators (often called IMSI catchers) and other interception technologies are in the United States and how adversaries use them.

The Assistant Secretary must consult a range of groups when preparing the report, including the FCC, NIST, the intelligence community, DHS components (CISA and S&T), academic and independent researchers, standards bodies (for example 3GPP and the IETF), international stakeholders (coordinated with the State Department), mobile service providers (including small and rural providers), manufacturers and developers, and other experts. The report is limited to mobile service networks and must exclude consideration of 5G protocols and networks. It must limit its vulnerability assessment to problems shown to be exploited outside labs or that are practicably exploitable in real-world conditions, and it must consider vulnerabilities already mitigated by device manufacturers. The report should be unclassified but may include a classified annex; potentially exploitable unclassified information must be redacted in the public version while the committees receive an unredacted copy.

The bill defines key terms such as "adversary" (including unauthorized hackers and certain foreign actors) and "mobile service" (commercial mobile service and commercial mobile data service). Sponsors listed in the metadata include Greg Landsman, Kat Cammack, Brian Fitzpatrick, Erin Houchin, and Zachary Nunn. The bill was received in the Senate and referred to the Senate Commerce, Science, and Transportation Committee.

What it means for you#

This bill itself does not change mobile services or device rules. It requires a federal report that will collect information about mobile network security, encryption, authentication, and surveillance tools. The report could inform Congress and federal agencies, but the bill does not itself order security upgrades or new regulations. Mobile providers, device makers, standards groups, researchers, and federal agencies may be asked to provide input for the report.

Expenses#

No publicly available information on cost estimates or funding for producing the report is included in the bill text or provided metadata.

Proponents' View#

No publicly available information on proponents' arguments or statements beyond the sponsor names and bill text.

Opponents' View#

No publicly available information on opponents' arguments or statements in the bill text or provided metadata.